CVE detail
CVE-2004-1460 — CVE-2004-1460
Published 2004-12-31 · Modified 2026-06-16 · Vendor cisco · Product secure_access_control_server · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0157
EPSS probability
exploitation probability, 30d
73.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Cisco Secure Access Control Server (ACS) 3.2(3) and earlier, when configured with an anonymous bind in Novell Directory Services (NDS) and authenticating NDS users with NDS, allows remote attackers to gain unauthorized access to AAA clients via a blank password.
Remediation
| Product | Vulnerable range | Fixed version | Advisory |
|---|
| n/a n/a | — | not specified | advisory ↗ |
References